Fork CMS contains a SQL injection vulnerability in versions prior to version 5.11.1. When deleting submissions which belong to a formular (made with module FormBuilder
), the parameter id[]
is vulnerable to SQL injection.
もっと詳しく